US2013291063A1PendingUtilityA1

Identification of Unauthorized or Misconfigured Wireless Access Point Using Distributed Endpoints

Assignee: ESCAMILLA TERRY DWAINPriority: Apr 25, 2012Filed: Apr 25, 2012Published: Oct 31, 2013
Est. expiryApr 25, 2032(~5.8 yrs left)· nominal 20-yr term from priority
H04W 24/06H04W 12/122H04W 12/128
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system for identifying unauthorized and/or misconfigured wireless access points (WAPs) in a communication network includes multiple network endpoints and multiple agents running on endpoints. The agents are adapted to periodically locate WAPs and to report located WAPs to a central entity. The system further includes a central entity operative to receive information from the agents regarding located WAPs, to determine whether at least a given one of the located WAPs needs to be probed, and to initiate active probing of located WAPs when it is determined that the given one of the located WAPs needs to be probed.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system for identifying at least one of unauthorized and misconfigured wireless access points (WAPs) in a communication network, the system comprising:
 a plurality of network endpoints;   a plurality of agents running on the plurality of endpoints, the agents being adapted to periodically locate WAPs and to report located WAPs to a central entity; and   a central entity operative to receive information from the plurality of agents regarding located WAPs, to determine whether at least a given one of the located WAPs needs to be probed, and to initiate active probing of located WAPs when it is determined that the given one of the located WAPs needs to be probed.   
     
     
         2 . The system of  claim 1 , wherein the active probing of located WAPs is performed by an agent running on a corresponding endpoint. 
     
     
         3 . The system of  claim 1 , wherein the central entity is operative to apply one or more prescribed business criteria for determining whether the at least one of the located WAPs needs to be probed. 
     
     
         4 . The system of  claim 1 , wherein at least a subset of the agents is operative to locate one or more WAPs in the communication network during prescribed time intervals. 
     
     
         5 . The system of  claim 4 , wherein the prescribed time intervals during which the subset of the agents is operative to locate one or more WAPs are periodic. 
     
     
         6 . The system of  claim 1 , wherein the central entity comprises:
 a receiving module adapted to receive information from one or more of the WAPs;   a reporting and alerting module coupled with the receiving module;   a database coupled with the receiving module and the reporting and alerting module; and   a control module coupled with the database.   
     
     
         7 . The system of  claim 6 , wherein the central entity is operative, through at least one of the receiving module, the reporting and alerting module, the database, and the control module, to control at least one of the plurality of agents, to store in the database prescribed information for determining whether the at least one of the located WAPs needs to be probed, to receive one or more messages that traverse through a given WAP under observation and across the communication network, and to report a prescribed condition of the given WAP as a function of the received messages. 
     
     
         8 . The system of  claim 6 , wherein, under control of the control module, at least a subset of the plurality of network endpoints is operative to periodically monitor one or more corresponding WAPs. 
     
     
         9 . The system of  claim 6 , wherein the control module is operative to apply prescribed rules, stored in the database, for determining a configuration status of an observed WAP to thereby determine whether the observed WAP should be probed by at least one of the plurality of network endpoints. 
     
     
         10 . The system of  claim 1 , wherein in performing an active probe of a given WAP, and a network corresponding to the given WAP, a selected endpoint is operative to establish communication with the given WAP, to transmit at least one request to network resources, and to observe a response from the given WAP to the at least one request. 
     
     
         11 . The system of  claim 10 , wherein the at least one request comprises a dynamic host configuration protocol ping. 
     
     
         12 . A computer program product for identifying at least one of unauthorized and misconfigured wireless access points (WAPs) in a communication network, said computer program product comprising a computer readable storage medium having computer readable program code embodied therewith, said computer readable program code comprising:
 computer readable program code configured to cause an agent running on an endpoint in the communication network to locate one or more WAPs in the communication network;   computer readable program code configured to cause the agent to report at least one located WAP to a central entity;   computer readable program code configured to cause the central entity to perform steps of applying prescribed criteria to determine whether the at least one located WAP needs to be probed, and initiating active probing of the at least one located WAP when it is determined that the at least one located WAP needs to be probed to thereby determine whether the located WAP is at least one of unauthorized and misconfigured.   
     
     
         13 . An apparatus for identifying at least one of unauthorized and misconfigured wireless access points (WAPs) in a communication network, the apparatus comprising:
 at least one processor, the at least one processor being operative: (i) to initiate an agent to run on at least one endpoint in the communication network, the agent being adapted for locating one or more WAPs in the communication network; (ii) to receive from the agent information relating to at least one located WAP; (iii) to apply prescribed criteria for determining whether the at least one located WAP needs to be probed; and (iv) to initiate active probing of the at least one located WAP when it is determined that the at least one located WAP needs to be probed to thereby determine whether the located WAP is at least one of unauthorized and misconfigured.

Join the waitlist — get patent alerts

Track US2013291063A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.